CASE DOSSIER investigation

3CX DesktopApp Cascading Supply Chain Attack (Lazarus Group)

Docket: Mandiant-3CX-Investigation-2023 Court: National Cyber Security Centre & Mandiant Forensic Reports Opened: 2023-03-29 Sector: Telecommunications & Enterprise VoIP

Key Facts

Status
INVESTIGATION
Legal disposition
Loss Amount
$85.0 million
Global enterprise security containment, code signing certificate revocations, and application rebuilds.
Techniques
2
Verified mappings
Defendants
0
Named in charges
  • Legal Status: INVESTIGATION in National Cyber Security Centre & Mandiant Forensic Reports.
  • Primary Target Sector: Telecommunications & Enterprise VoIP.
  • Documented Financial Loss: $85.0 million.
  • 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

North Korean state-sponsored threat group Lazarus compromised VoIP communications software provider 3CX, injecting malware into digitally signed Windows and macOS builds of 3CXDesktopApp downloaded by over 600,000 corporate customers, in the first documented case of one software supply chain compromise directly enabling a second downstream supply chain breach.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Unauthorized intrusion originating from targeted infiltration directed against Telecommunications & Enterprise VoIP networks. North Korean state-sponsored threat group Lazarus compromised VoIP communications software provider 3CX, injecting malware into digitally signed Windows and macOS builds of 3CXDesktopApp downloaded by over 600,000 corporate customers, in the first documented case of one software supply chain compromise directly enabling a second downstream supply chain breach.

Operational & Financial Fallout

Global enterprise security containment, code signing certificate revocations, and application rebuilds. Impacted Telecommunications & Enterprise VoIP infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: INVESTIGATION
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Unauthorized intrusion originating from targeted infiltration directed against Telecommunications & Enterprise VoIP networks. North Korean state-sponsored threat group Lazarus compromised VoIP communications software provider 3CX, injecting malware into digitally signed Windows and macOS builds of 3CXDesktopApp downloaded by over 600,000 corporate customers, in the first documented case of one software supply chain compromise directly enabling a second downstream supply chain breach.

Adversary Kill Chain Flow

2 Documented Phases
1
Phase 1: Infiltration Perimeter Ingress
MITRE ATT&CK T1190 →

Operatives secured access to victim infrastructure within the Telecommunications & Enterprise VoIP sector.

Artifacts & Tooling: Network perimeter logs
2
Phase 2: Execution Payload Deployment
MITRE ATT&CK T1486 →

North Korean state-sponsored threat group Lazarus compromised VoIP communications software provider 3CX, injecting malware into digitally signed Windows and macOS builds of 3CXDesktopApp downloaded by over 600,000 corporate customers, in the first documented case of one software supply chain compromise directly enabling a second downstream supply chain breach.

Artifacts & Tooling: Malicious payload
Real-World Blast Radius & Operational Fallout

Global enterprise security containment, code signing certificate revocations, and application rebuilds. Impacted Telecommunications & Enterprise VoIP infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2023-03-08 incident

3CX signs and distributes trojanized desktop application update to global customers.

2023-03-29 discovery

CrowdStrike and SentinelOne publicly flag 3CXDesktopApp as malicious.

2023-04-20 disclosure

Mandiant reveals initial compromise stemmed from employee downloading infected Trading Technologies software.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1195.002
"Malicious code was compiled into ffmpeg.dll and d3dcompiler_47.dll, which were digitally signed by 3CX legitimate Apple and Windows certificates." Mandiant Technical Report: 3CX Software Supply Chain Compromise reviewed
T1071.001 Web Protocols
Command and Control
"The backdoored desktop client pulled encrypted icon files containing base64 command-and-control server domains from public GitHub repositories." CISA Alert AA23-090A reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, 3CX DesktopApp Cascading Supply Chain Attack (Lazarus Group), No. Mandiant-3CX-Investigation-2023 (National Cyber Security Centre & Mandiant Forensic Reports 2023), https://cybercaselibrary.com/cases/3cx-desktop-app-supply-chain/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/3cx-desktop-app-supply-chain" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>